The Problem That Sparked the Idea
A client’s security champion program tried to introduce threat modeling to development teams. It was not sticky. Developers saw it as a time drain and a dry exercise. Harris had just finished a D&D campaign with a separate group. He saw a corollary between D&D and threat modeling. After months of thought, he produced a first iteration. He brought it to Threat Modeling Con in Washington D.C. as a live 2‑hour tabletop exercise. Participants used physical cards printed with D&D lore. The same format ran again at a threat modeling hackathon using Lucid Spark.
Assembling the Party and Mapping the World
A cross‑functional team is required: developers (warriors), architects (diagramancers), QA testers (rangers), and a facilitator (bard). The bard maintains the story and artifacts. Every session needs a data flow diagram — pre‑existing or built from scratch on a whiteboard or in Miro. Harris brought D&D character cards, an XP tracker, and 24 monster/safeguard cards. The party earns 5 XP for adding a previously unknown component to the diagram. The first step is to review the map and ensure it reflects current production state.
Identifying Monsters with STRIDE‑Aligned Cards
Harris created 24 threat and mitigation cards aligned to STRIDE. Each monster has a D&D backstory that maps to a STRIDE category. The gluttonous slime represents denial of service because it consumes resources. The mimic of trust maps to spoofing. Developers play a card on the data flow diagram and explain why that threat exists at that vector. The bard guides the conversation. The goal is to name real threats in a tangible way. Developers started using monster names like “the gluttonous slime” instead of STRIDE terms.
Prioritizing with a Challenge Rating Matrix
Impact and likelihood are assessed using a D&D‑themed matrix. Damage dice measure impact; saving throws measure likelihood. A critical‑hit threat with legendary impact and easy exploitation earns 8 XP. The matrix helps developers understand priority without requiring deep security expertise. XP is tracked on a leaderboard. In one session, top XP earners received a custom D20 die and other D&D swag. The competition drove deeper threat identification.
Mitigations, Iteration, and Recognition
Mitigation cards are also STRIDE‑aligned and assign flat XP values. The party rotates through threats and selects the appropriate safeguard. Harris advocates making progress visible: post the XP chart, give public shout‑outs, and rotate the bard role across sessions. Threat modeling should be iterative — revisit the diagram every sprint or quarter. Recognition is the strongest tool for behavior change. “Acknowledgment is the strongest way to get repeat behavior change in human beings generally,” Harris said.
Q&A
Have you tried other gaming platforms besides D&D? Harris has used Adam Shostack’s Elevation of Privilege card game for audiences less familiar with D&D. He is also exploring a board‑game version. ▶ 28:52
Does the challenge rating matrix cause team members to overvalue threats? Overestimation is natural and invites productive conversation. A security expert or business sponsor can provide real impact data. Harris deliberately encourages overestimating so the team can discuss why a threat is catastrophic. â–¶ 29:54
Notable Quotes
I went along this path of creating 24 different threat and mitigation cards, all inspired by a variety of Dungeons and Dragons lore.
Stanley Harris · ▶ 12:00
when you hear a developer say, “I have a solution to defeat uh the the gluttonous slime.” I mean, it’s kind of cool.
Stanley Harris · ▶ 24:47
naming the threats kind of gives you a power to defeat them.
Stanley Harris · ▶ 24:32
acknowledgement is the strongest way to get repeat behavior change in human beings generally.
Stanley Harris · ▶ 21:03
Key Takeaways
- Use role‑playing elements (character cards, XP, monster names) to make threat modeling tangible.
- A 2‑hour session with 24 STRIDE‑aligned cards can surface real threats and mitigation plans.
- Public recognition and XP leaderboards drive repeat engagement and behavior change.
About the Speaker
Stanley Harris is the CEO and co‑founder of Katilyst. He helps companies build Security Champion programs designed to scale. As a software security advocate, he focuses on building strong relationships between development and security teams. In his spare time, Stanley works…